Password Generator

Generate strong random passwords or memorable passphrases. Length, character classes, bulk mode — all local.

Length20
Press Generate

Pick options above and hit Generate.

01 — Overview

How the Password Generator works

Two modes: random passwords with configurable length and character classes (upper, lower, digits, symbols), or XKCD-style passphrases built from a wordlist. Generate one or hundreds at a time. Every byte of randomness comes from the Web Crypto API; nothing leaves your browser.

02 — Use cases

When to use the Password Generator

  1. 01

    Generate a strong password for a new service

  2. 02

    Build a memorable passphrase for a master password

  3. 03

    Bulk-generate test passwords for a load test or fixture

  4. 04

    Quickly rotate a credential without leaving the browser

03 — Examples

Password Generator examples

20 chars, all classes

ex 01

T7%dKp9!Lv3@Qx2&Wm8z

Cryptographically random, includes upper, lower, digit, symbol.

passphrase, 5 words, hyphen separator

ex 02

stellar-amber-quiet-cobalt-river

Memorable but ~64 bits of entropy.

32 chars, letters and digits only

ex 03

k7Rm2QpXvL9dTyN4wBzH6cJfA3sEuG8r

For systems that silently truncate or reject symbols — still roughly 190 bits.

passphrase, 7 words, space separator

ex 04

cobalt lantern quiet meadow bronze drift wren

Around 90 bits of entropy, and typeable on a phone or a TV remote.

04 — FAQ

Password — frequently asked questions

Are these passwords safe to use?

The randomness comes from window.crypto.getRandomValues — the same source recommended for security-sensitive use in the browser. Passwords never leave your device.

Random or passphrase?

Random passwords pack more entropy per character. Passphrases are dramatically easier to remember and type. For a master password you'll type weekly, passphrases win. For a vault entry, random.

How many bits of entropy do I need?

≥80 bits is comfortably safe for anything not nation-state targeted. The tool shows entropy live so you can size length to your threat model.

Should I still require symbols and mixed case?

NIST SP 800-63B dropped composition rules in its current guidance. They push people toward predictable substitutions — Password1! and its variants — while adding little real entropy. Length plus a blocklist of known-breached passwords does far more, which is why the passphrase mode here defaults to five words.

Do passwords need to be rotated every 90 days?

NIST advises against scheduled rotation. Forced expiry makes people iterate — spring2026, summer2026 — which is easier to guess than the original. Rotate on evidence of compromise instead: a breach notification, a shared credential, or someone leaving the team.

Does anything I generate here leave the browser?

No. Every byte comes from crypto.getRandomValues() in your own browser, and no generated password is sent anywhere, logged, or stored. You can confirm it by generating with the network tab open, or by loading the page and then going offline.

05 — Reference

Specs and further reading

The primary sources this tool follows. Where behaviour is defined by a specification, we link the specification rather than a summary of it.

07 — More

Tools that pair with Password

Last updated .